Uncontrolled Memory Allocation in OpenSSL - CVE-2022-1473
Published: May 3, 2022 / Updated: October 28, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform denial of service (DoS) attack.
The vulnerability exists due to memory reuse is not possible in the OPENSSL_LH_flush() function, which empties a hash table when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without bounds and the process might be terminated by the operating system causing a denial of service.
Affected software
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Ubuntu
Junos OS Evolved
Isolation Segment
VMware Tanzu Application Service for VMs
EasyApache
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM Integration Bus
IBM QRadar WinCollect Agent
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Engineering Workflow Management
Steel Belted Radius Carrier Edition
SINAMICS GL150
SINAMICS PERFECT HARMONY GH180 6SR5
SINAMICS SL150
SCALANCE S615
cflinuxfs3
Tanzu Greenplum for Kubernetes
Brownfield Connectivity - Client
Platform Automation Toolkit
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libssl1.0.0 (Ubuntu package)
dev-libs/openssl
libssl1.1 (Ubuntu package)
openssl (Red Hat package)
libopenssl-3-devel
libopenssl3-32bit-debuginfo
libopenssl3-32bit
libopenssl-3-devel-32bit
openssl-3-doc
openssl-3-debugsource
openssl-3-debuginfo
openssl-3
libopenssl3-debuginfo
libopenssl3
libssl3 (Ubuntu package)
openssl
IBM App Connect Enterprise
Engineering Lifecycle Management
VMware Tanzu Operations Manager
SCALANCE M812-1 ADSL-Router (Annex B)
RUGGEDCOM RM1224 LTE(4G) EU
RUGGEDCOM RM1224 LTE(4G) NAM
SCALANCE M804PB
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M826-2 SHDSL-Router
SCALANCE M874-2
SCALANCE M874-3
SCALANCE M876-3 (EVDO)
SCALANCE M876-3 (ROK)
SCALANCE M876-4
SCALANCE M876-4 (EU)
SCALANCE M876-4 (NAM)
SCALANCE MUM853-1 (EU)
SCALANCE MUM856-1 (EU)
SCALANCE MUM856-1 (RoW)
SCALANCE S615 EEC
How to mitigate CVE-2022-1473
Isolation Segment - addressed in versions 2.7.45, 2.10.25, 2.11.14, 2.12.8
VMware Tanzu Application Service for VMs - addressed in versions 2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5
cflinuxfs3 - update to 0.292.0
Tanzu Greenplum for Kubernetes - update to 2.0.0
EasyApache - update to 4 2022-5-11
IBM QRadar WinCollect Agent - update to 10.0.2
IBM App Connect Enterprise - update to 12.0.5.0
Junos OS Evolved - addressed in versions 22.1R3-EVO, 22.2R1-EVO
libssl1.0.0 (Ubuntu package) - addressed in versions 1.0.2g1ubuntu4.20+esm3, 1.0.2n-1ubuntu5.9
dev-libs/openssl - update to 1.1.1q
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1l-1ubuntu1.3, 1.1.1f-1ubuntu2.13, 1.1.1-1ubuntu2.1~18.04.17
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
Brownfield Connectivity - Client - update to 2.15
openssl (Red Hat package) - update to 3.0.1-41.el9_0
libopenssl-3-devel - update to 3.0.1-150400.4.7.1
libopenssl3-32bit-debuginfo - update to 3.0.1-150400.4.7.1
libopenssl3-32bit - update to 3.0.1-150400.4.7.1
libopenssl-3-devel-32bit - update to 3.0.1-150400.4.7.1
openssl-3-doc - update to 3.0.1-150400.4.7.1
openssl-3-debugsource - update to 3.0.1-150400.4.7.1
openssl-3-debuginfo - update to 3.0.1-150400.4.7.1
openssl-3 - update to 3.0.1-150400.4.7.1
libopenssl3-debuginfo - update to 3.0.1-150400.4.7.1
libopenssl3 - update to 3.0.1-150400.4.7.1
libssl3 (Ubuntu package) - update to 3.0.2-0ubuntu1.1
openssl - update to 3.0.5-1
Platform Automation Toolkit - addressed in versions 4.4.29, 5.0.22
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.2
Engineering Workflow Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE S615 - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
SCALANCE M804PB - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M874-2 - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE S615 EEC - update to 7.2
Steel Belted Radius Carrier Edition - update to 8.6.0R16
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- Ubuntu update for openssl
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- Multiple vulnerabilities in cPanel EasyApache
- Ubuntu update for openssl
- Multiple vulnerabilities in IBM QRadar WinCollect Agent
- Multiple vulnerabilities in IBM App Connect Enterprise and IBM Integration Bus
- Multiple vulnerabilities in IBM Tivoli Netcool System Service Monitors/Application Service Monitors
- SUSE update for openssl-3
- VMware Tanzu products update for OpenSSL
- Red Hat Enterprise Linux 9 update for openssl
- Gentoo update for OpenSSL
- Multiple vulnerabilities in Juniper Networks Steel Belted Radius Carrier Edition
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilites in Siemens Brownfield Connectivity - Client
- Multiple vulnerabilities in Siemens RUGGEDCOM and SCALANCE Products
- VMware Tanzu products update for OpenSSL
- Multiple vulnerabilities in Siemens Integrated SCALANCE S615 of SINAMICS Medium Voltage products
- Multiple vulnerabilities in IBM Engineering Workflow Management (EWM)
- Junos OS Evolved update for OpenSSL
- Amazon Linux AMI update for openssl